Vulnerability Description
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 1.3, <= 1.3.32 |
| Openpkg | Openpkg | 2.0 |
| Hp | Hp-Ux | 11.00 |
| Slackware | Slackware Linux | 8.0 |
| Suse | Suse Linux | 8.0 |
| Trustix | Secure Linux | 1.5 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=109906660225051&w=2Mailing ListThird Party Advisory
- http://secunia.com/advisories/12898/Broken Link
- http://secunia.com/advisories/19073Broken Link
- http://securitytracker.com/id?1011783Broken LinkThird Party AdvisoryVDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmThird Party Advisory
- http://www.apacheweek.com/features/security-13Product
- http://www.debian.org/security/2004/dsa-594Mailing ListThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:134Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2004-600.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-816.htmlBroken Link
- http://www.securityfocus.com/bid/11471Broken LinkExploitPatch
- http://www.vupen.com/english/advisories/2006/0789Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17785Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab3827Mailing ListPatch
FAQ
What is CVE-2004-0940?
CVE-2004-0940 is a vulnerability with a CVSS score of 7.8 (HIGH). Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents ...
How severe is CVE-2004-0940?
CVE-2004-0940 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0940?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Openpkg Openpkg, Hp Hp-Ux, Slackware Slackware Linux, Suse Suse Linux.